CVE Tools

Pterodactyl/panel

16 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Pterodactyl/panel, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Pterodactyl/panel CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Pterodactyl/panel CVEs per month
MonthCVEs
2024-101
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-061
2025-070
2025-080
2025-090
2025-100
2025-110
2025-121
2026-013
2026-022
2026-030
2026-040
2026-050
2026-061
2026-070
2026-080
2026-090

Severity

How the 16 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical19%
  • High327%
  • Medium764%

Latest CVEs

The 15 most recently published vulnerabilities affecting Pterodactyl/panel.

  1. GHSA-j7f5-gfqm-pcx3Pterodactyl Panel: Client email change endpoint allows enumeration of accounts in system—
  2. CVE-2026-26016Pterodactyl Panel Allows Cross-Node Server Configuration Disclosure via Remote API Missing Authorization8.1
  3. GHSA-hr7j-63v7-vj7gPterodactyl Panel's SFTP sessions remain active after user account deletion or password change—
  4. CVE-2025-69198Pterodactyl's improper resource locking allows raced queries to create more resources than alloted6.5
  5. CVE-2025-69197Pterodactyl TOTPs can be reused during validity window6.5
  6. CVE-2025-68954Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced5.4
  7. GHSA-mgr9-6c2j-jxrqPterodactyl has a Reflected XSS vulnerability in “Create New Database Host”—
  8. CVE-2025-49132Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution10.0
  9. CVE-2024-49762Pterodactyl Panel has plain-text logging of user passwords when two-factor authentication is disabled4.6
  10. CVE-2024-34067Multiple cross site scripting (XSS) vulnerabilities in the admin area of Pterodactyl panel6.1
  11. GHSA-7v3x-h7r2-34jvInsufficient Session Expiration in Pterodactyl API—
  12. CVE-2021-41273Cross-Site Request Forgery allowing sending of test emails and generation of node auto-deployment keys4.3
  13. CVE-2021-41176logout CSRF in Pterodactyl Panel4.3
  14. CVE-2021-41129Authentication bypass in Pterodactyl8.1
  15. GHSA-5822-pw57-vv37XSS vulnerability when listing users on add & modify server pages.—

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store